Browse live malware projects

Implant Configuration Extraction and C2 Channel Profiling

Botnets & C2

The organization observed regular, low-volume outbound connections from several workstations that align with automated beacon timing. We need a researcher to characterize the beacon interval, jitter, and encoding, then determine whether the host is enrolled in a command-and-control channel and how to scope the wider footprint.

Budget: $3,900 - $7,350

Phishing Wave Triage: Malicious Word Attachment Reaching Finance Inboxes

Macro & Document Malware

The organization received a wave of emails carrying a macro-enabled Office attachment that bypassed initial filtering. We need a researcher to safely deobfuscate the embedded VBA, document the staging behavior without executing the payload, and deliver an IOC set plus mail-gateway hardening guidance.

Budget: $5,100 - $9,550

JavaScript Card Skimmer Detected on E-Commerce Payment Page

Website / Web Malware

Visitors on mobile devices are being silently redirected from our WordPress site to questionable third-party pages, while desktop traffic looks fine. We want the conditional redirect logic found, removed, and the entry point identified so it does not return.

Budget: $3,300 - $6,150

Beacon Traffic Analysis on Suspected Compromised Endpoints

Botnets & C2

We have one confirmed malicious sample and very little context. We need it pivoted outward into a connected infrastructure graph, mapping the C2 endpoints, supporting domains, and any shared hosting or registration signals that tie the nodes together into a single operation.

Budget: $4,750 - $8,950

Autorun-Driven Removable-Media Worm Cleanup and Policy Hardening

Worms & Self-Propagating

A self-propagating worm has spread laterally across multiple network segments faster than manual cleanup can keep pace. The client needs an analyst to map the propagation path, identify patient zero, and recommend containment so reimaged hosts stop getting reinfected.

Budget: $750 - $1,450

Periodic Outbound Callback Investigation on Finance Subnet

Botnets & C2

Encrypted callbacks are obscuring what an implant is actually doing, and we need help reconstructing the command channel. The researcher should decode the beacon structure where feasible, reconstruct the sleep and check-in pattern, and explain what tasking the operator could plausibly issue.

Budget: $1,750 - $3,300

Credential-Harvesting Malware Detected by EDR — Scope and Containment

Computer / Endpoint Malware

EDR telemetry indicates credential-harvesting activity on a handful of endpoints, but the client lacks in-house reverse-engineering capacity to confirm. They need an analyst to validate the detection, determine which credentials are exposed, and recommend rotation priorities. Evidence handling must remain insurance- and audit-grade throughout.

Budget: $1,550 - $2,950

Suspected Loader-Dropper Chain on Finance Workstations

Computer / Endpoint Malware

EDR telemetry indicates credential-harvesting activity on a handful of endpoints, but the client lacks in-house reverse-engineering capacity to confirm. They need an analyst to validate the detection, determine which credentials are exposed, and recommend rotation priorities. Evidence handling must remain insurance- and audit-grade throughout.

Budget: $850 - $1,600

USB-Propagated Worm Eradication Across Air-Gapped Plant Floor

Worms & Self-Propagating

Removable USB drives carried a worm onto an isolated production network, and infected machines keep reappearing after cleanup. We need help confirming the propagation mechanism, scoping every affected endpoint, and closing the autorun and trust gaps that allow reinfection.

Budget: $3,600 - $6,750